Tag: emerging threats
4849 articles

Account Takeovers Rise as Complexity Exposes Identity Vulnerabilities
As attackers increasingly target identities rather than infrastructure, account takeovers are on the rise - and with 22% of breaches involving credential abuse, it's clear that traditional username-and-password security just isn't cutting it. The explosion of identities across cloud services, SaaS apps, and remote environments has created a perfect storm of vulnerability.

Homebrew Bolsters Security with 6.0 Release
Homebrew just got a major security boost with its 6.0 release, introducing a new security mechanism and Linux sandbox to keep things safe and secure. This latest update, which landed on June 17, 2026, promises even more under the hood.

Telegram Exposes India's Internet Routing Risks in Dispute Over Exam Fraud
Telegram CEO Pavel Durov accused an Indian telecom of sabotaging the platform's service outside of India, amid a dispute over exam fraud that led to nationwide restrictions on the app. The company is now fighting back in court against the Indian government's orders.

Enterprise Data Uploads to AI Models Surge 93% in a Year
In just one year, enterprise data uploads to AI models have skyrocketed 93%, with a staggering 18,033 terabytes of data - equivalent to 3.6 billion digital photos - being transferred to AI and machine learning applications. This massive surge raises serious concerns about data breaches and cyber espionage.

AI-Powered Attacks Exacerbate Alert Fatigue in Cybersecurity Teams
Cybersecurity teams are drowning in data, but struggling to turn it into action - and AI-powered attacks are making alert fatigue worse. With AI-powered attacks topping the list of concerns for 41% of cybersecurity leaders, it's clear that teams need a new approach to stay ahead.

Validation Turns Security Visibility into Action
Despite pouring resources into security tools for better visibility, many teams still struggle to turn insights into action, leaving them overwhelmed by endless findings with unclear priorities. It's time to bridge the gap between detection and response to truly fortify digital defenses.

Microsoft Probes Office App Launch Issues Tied to June Updates
Microsoft is investigating a frustrating issue that prevents some third-party apps from launching Office applications or opening documents after installing recent Windows updates. This problem, affecting Word, Excel, PowerPoint, and more, leaves users unable to access their files or work smoothly.

Dutch Police Disrupt Helpdesk Scam Ring with In-Person Tactics
Dutch police stormed a makeshift call centre in Amsterdam, catching six suspects in the act of running a helpdesk scam ring and making off with multiple laptops, phones, and bank cards. The daring raid, which happened on June 10, has put a dent in the operation, but police warn that further arrests may be on the horizon.

Exposed Services Fuel Rapid Exploitation of Enterprise Networks
Did you know that 60% of organizations have at least one HTTP panel exposed to the internet, leaving them vulnerable to rapid exploitation by cyber attackers? In today's threat landscape, this kind of exposure can turn into a security breach in just 24 hours.

Malicious Plugins Exfiltrate AI API Keys
Beware of malicious AI plugins masquerading as coding assistants on the JetBrains Marketplace - they might just steal your AI API keys. These 15 sneaky plugins, active since October 2025, cleverly exfiltrate API keys to attacker-controlled servers, all while functioning as promised.

CISA Mandates Patching of Joomla Plugin Flaw by Friday
Don't wait until it's too late - CISA is requiring Federal agencies to patch a critical Joomla plugin flaw by Friday, as hackers can exploit it to upload and execute malicious PHP code. The vulnerability, found in the Widget Factory Joomla Content Editor, allows unauthenticated users to create new editor profiles and poses significant risks to your online security.

Staffing Shortages Plague Security Operations Centers
The 2026 SANS SOC Survey reveals a disconnect: while 79% of respondents use AI or machine learning tools, only 36% have integrated them into a defined workflow, highlighting a key challenge in Security Operations Centers. Practitioners cite staffing shortages as their top operational challenge, but leaders seem less concerned.

Malicious Plugins Exfiltrate AI API Keys on JetBrains Marketplace
Beware of malicious AI plugins on the JetBrains Marketplace that masquerade as helpful coding assistants but secretly steal your AI API keys. Over 70,000 installations have been recorded from at least 15 compromised plugins that have surprisingly evaded the marketplace's security checks.

Organizations' Crisis Response Lags Behind Confidence Levels
Most companies are blissfully unaware of impending crises, with a staggering 93% admitting they've missed warning signs of disruptions - and it's costing them dearly, with every business surveyed reporting a significant financial hit.

AI Code Review Foils Malicious Backdoor in Python Project
When Roman Imankulov analyzed a suspicious Python project with his AI agent, it quickly flagged a malicious backdoor, saving him from a potentially disastrous mistake. The AI code review proved to be a crucial safeguard, alerting Imankulov to walk away from the tainted code.

Mastra Packages Compromised in Software Supply Chain Attack
A massive software supply chain attack just hit Mastra, with over 140 malicious packages published in a single day by a compromised npm account. The swift and coordinated assault, dubbed easy-day-js, unfolded over just two days, catching defenders scrambling to respond.

Microsoft Scrambles to Patch RoguePlanet Zero-Day in Defender
Microsoft is racing against the clock to fix a critical vulnerability in Defender, known as RoguePlanet, after a proof-of-concept exploit was released, allowing hackers to elevate privileges regardless of real-time protection settings. A patch is in the works, but no release date has been given.

Kodak Breach Exposes Sensitive Data After ShinyHunters Hack
Kodak recently suffered a data breach at the hands of hackers known as ShinyHunters, who gained temporary access to sensitive company data. The company has launched a swift investigation with external cybersecurity experts and is working closely with law enforcement to mitigate the impact.

UK Defence Chief Warns of Reduced Operations Without Extra Funding
UK Defence Chief Richard Knighton warns that without a boost in funding, the country's military operations will have to be scaled back, putting routine activity at risk. He urges Prime Minister Keir Starmer and the Treasury to take action to secure the necessary budget.

US Power Anchors South China Sea Maritime Rights
A free and open South China Sea region won't become a reality through mere wishful thinking - it demands decisive action, strong deterrence, and a unified response to China's increasingly assertive moves. The Philippines has aptly described China's strategy as "talk and take," where diplomatic engagement goes hand-in-hand with the incremental expansion of its physical presence and control.

Defense Agency Taps AI to Accelerate Security Clearance Reviews
The Defense Counterintelligence and Security Agency is harnessing the power of AI to supercharge security clearance reviews, cutting processing time from months to just hours. By automating narrow tasks and escalating them to human reviewers, the agency is streamlining the vetting process like never before.

DIU Awards Contract to Mach Industries for Long-Range Strike Drone
The Defense Innovation Unit has partnered with Mach Industries to develop Atlas, a game-changing, long-range strike drone that can take off and land like a helicopter but fly like a plane, requiring minimal infrastructure. This innovative aircraft is set to revolutionize expeditionary strike capabilities with its unparalleled control simplicity and efficiency.

AI Models' Rapid Updates Expose Security Gaps
Researchers uncovered over 30 security patches for Anthropic's Claude Code in just two months, revealing a concerning pattern of brief, often silent vulnerabilities as AI models are rapidly updated. This finding highlights the need for greater transparency and scrutiny in the high-stakes world of AI model security.

Navy Overhauls Science Strategy to Accelerate Tech Deployment
The Navy is revolutionizing its approach to science and technology with a bold new strategy that prioritizes speed and selectivity in deploying cutting-edge tech to those who need it most. By fostering closer collaboration with key stakeholders, the Office of Naval Research aims to rapidly deliver game-changing innovations to sailors and marines.